A misconfigured Active Directory Certificate Services (AD CS) template can let any Domain User enroll for a client-authentication certificate while supplying an arbitrary subject, allowing an attacker to obtain a certificate impersonating another user—including an administrator. The attacker can then authenticate to a domain controller, obtain a Kerberos ticket-granting ticket (TGT), and escalate privileges across the Active Directory domain. Windows certutil.exe supports administration and inspection of certificates, certificate authorities, stores, keys, and certificate revocation lists, and can help defenders review PKI configurations and artifacts.
GuidePoint Security identified a forensic visibility issue in the go-ese library: it decoded AD CS CA-database timestamps as OLE dates rather than Windows FILETIMEs, producing misleading 1899-12-30 dates. The merged fix distinguishes valid OLE dates from misinterpreted FILETIMEs based on the decoded float range, and Velociraptor 0.76.6 incorporates the corrected dependency, enabling VQL-based hunting for suspicious AD CS certificate requests. Organizations should audit certificate-template enrollment permissions, client-authentication usage, and subject-supply settings, then investigate anomalous certificate issuances associated with privileged accounts.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
A VQL artifact was developed to detect suspicious ADCS certificate-request activity associated with the described abuse technique. A pull request was submitted to the Velociraptor Artifact Exchange to make the hunting and analysis capability available to investigators.
Velociraptor updated its go.mod to use the corrected go-ese module, and version 0.76.6 includes the fix. Earlier Velociraptor releases return 1899-12-30T00:00:00Z for affected DateTime fields in ADCS CA databases.
A fix was merged into the official Velocidex go-ese repository that treats Flags=0 values as OLE dates only when their float64 value exceeds 1.0, otherwise decoding them as Windows FILETIMEs. The approach corrected ADCS parsing without breaking SRUDB.dat, which legitimately uses OLE dates.
Analysis of the ADCS CA database found that its DateTime fields were stored as Windows FILETIMEs despite being marked Flags=0, causing go-ese to decode them as OLE dates and return timestamps near 1899-12-30. Decoding the raw values as FILETIMEs matched timestamps reported by certutil.
Researchers described an ADCS certificate template that allowed all Domain Users to enroll, supported Client Authentication, and permitted enrollee-supplied subjects. An attacker could request a certificate for another user, authenticate to a domain controller as an administrator, obtain a Kerberos TGT, and act with that administrator's privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.